cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
652
Views
0
Helpful
9
Replies

3000 Concentrator and Integrity.

wuh
Level 1
Level 1

Guys:

We have Cisco Concentrator 3000 for our VPN users and Checkpoint Integrity for firewall for these users' computers. It works fine for XP and MAC.

But it won't work with Vista. Everytime when a user connects to VPN concentrator,

it'd be "restricted" by the integrity server. But our integrity support can't find the problem. Anyone has idea about this?

Thanks and Happy New Year!

Han

9 Replies 9

carenas123
Level 5
Level 5

Here is some steps it may help you for the integrity server.

Step 1 Configure firewall policy on the Integrity Server (IS).

Step 2 On the VPN Concentrator, go to Configuration | System | Servers | Firewall Server. For the Zone Labs Integrity Server, enter the host name or IP address and the port number.

Step 3 Under Configuration | User Management | Base Group or Groups | Client FW tab, configure the following:

a. Firewall Setting = Firewall Required

b. Firewall = Zone Labs Integrity

c. Firewall Policy = Policy from Server

Step 4 Save the configuration.

Here is the URL for the Configuring the VPN Client on a VPN 3000 Series Concentrator follow the guide it may help you

http://www.cisco.com/en/US/docs/security/vpn_client/cisco_vpn_client/vpn_client500_501/administration/5vcAch4.html

Thanks, but i already did those. Our XP users work fine.

Han

Han

You mean to say, the vista users are connected onto vpn 3000, get an ip address , but are blocked by checkpoint firewall ? do you have ur setup ? is the firewall parallel to vpn 3000, or on inside ? do vista users get ip address from the same ip pool as XP users ?

Raj

are blocked by checkpoint firewall ? Yes. The VPN restricts it because the Integrity server tells it(How I am trying to figure out)

do you have ur setup ? Yes, Which part of configuration?

is the firewall parallel to vpn 3000, or on inside ? They are on the same subnet inside out network.

do vista users get ip address from the same ip pool as XP users ? Yes. Except they got restircted.

can you bypass the integrity server configuration and check if it works ? why is this integrity needed ? how is it cascaded with the vpn concentrator ? i think without the integrity part, it should work fine, as the layer 3 connecitivity is established, and the users would be able to access applications..

Let us know

Raj

Raj:

Yes, I tried and it works with integrity and it works with VPN.

Integrity is a firewall, which is pushed from the server to a VPN client. Out VPN is configured so that the vpn user can use the resource only after the integrity "says OK".

thanks,

Han

Han.. so , it is clearly a problem with the integrity stuff and i think they will have to solve this.. am i not right ?

honestly, I cannot tell.

The ZL client and server use Heartbeat for commnication. but they never received by the client. therefore the server doesnt put the policy to the client. as a result, the PC is restricted.

I can, however, connect to the VPN with the ZL.

I aslo can, get the ZL policy pushed correctly without a VPN.

So, all i can tell from this so far is there is a communication problem between this two servers that drops certian traffic of ZL.

thanks,

Han

I really dont understand this ZL client server setup :( do u have any diagrams to depict that ? I would run a sniffer on the ZL server port, and see what exactly is happening. If the firewall drops the communication, it can only be due to some NAT, ACL statements on it.. otherwise it should allow it ! Let us know..

Raj

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: